Re: Virus access to System Restore??



If malware is able to install something by leveraging admin context
then it can get to run as system which does have full access to the
system restore point storage.
When this has happened and you are insisting on not formatting
and installing fresh then you should shut off system restores so that
all gets delete and then turn it back on as a part of your cleanup.

"David Jones" <davejones@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0998E081-32E7-48BB-99CB-7248B4AE7CE7@xxxxxxxxxxxxxxxx
I just spent the day scanning my drives to remove some viruses.
- Yes I was at fault in that I didn't have antivirus sw on my system.. now
rectified
- Yes I shouldn't have gone to that site and accepted a downloaded codec
install

The av sw found 4 viruses including, as I suspected a fake virus alert:
The taskbar show (bottom right of screen) that there was a virus and
occassionally popped up meassage saying my machine was infected and to
click
there to install antimalware sw ... I wasn't fooled on that one
(It pointed to something like xxxxquake.com)

My question is this:
=============
The 4 viruses were in the System Volume Information folder as part of
System
Restore. How come virus software can inject into that folder. Surely it
should be trebly protected? I can't vene browse into myself as
administrator?

PS The viruses were 3xPuper and 1x Fake-Alert-B, all Trojan
Virus scan sw is MacAfee

The annoying thing is that I couldn't do a system restore after the virus
scan and removal.
--
David Jones
RMIT University



.



Relevant Pages

  • Re: Win XP HOME + MS Blaster (auto shutdown)
    ... Turn on computer but do not connect to the internet ... click to check off "Turn off System Restore", ... Run the virus cleaning tool (DO NOT CONNECT TO THE ... Install the MS Patch ...
    (microsoft.public.security.virus)
  • Re: NEED HELP...please
    ... Make sure your virus definition files are up-to-date. ... Viruses aren't the only thing that can leave your computer dead in the ... Download and install Lavasoft's "AdAware" program - the free one. ... If your XP "Internet Connection Firewall" isn't ...
    (microsoft.public.windowsxp.newusers)
  • Re: You do not have sufficient security privileges ...
    ... damage to the operating system can occur. ... The virus removal programs try to ... with the install cdrom handy. ... Many viruses will not allow a computer operating system to even start. ...
    (microsoft.public.win2000.security)
  • Re: I had a computer virus that ATT corrected but
    ... virus protector,but is in reality a virus. ... seeing isn't a sign that you have already got the malware -- it's part ... of the attempt to install it on your computer. ... a system restore to an earlier date, because if you have got the real ...
    (soc.retirement)
  • Re: I had a computer virus that ATT corrected but
    ... virus protector,but is in reality a virus. ... seeing isn't a sign that you have already got the malware -- it's part ... of the attempt to install it on your computer. ... a system restore to an earlier date, because if you have got the real ...
    (soc.retirement)